Microsoft Sentinel
Cloud and workloads

Stop SAP data collection

In brief

The article now distinguishes temporary stops, by pausing the SAP Cloud Integration Data Collector flow, from permanent stops, which involve removing SAP systems, undeploying the flow, and reversing SAP-side configuration. Optional cleanup of related Azure resources is also documented.

What Defender admins need to know

Administrators stopping an agentless SAP integration should follow these updated procedures instead of the previous container-based steps.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Stop SAP data collection in Microsoft Sentinel for SAP applications

There might be instances where you need to halt the data collection from your SAP applications by the Microsoft Sentinel agentless data connector agent,connector, whether for maintenance, troubleshooting, or other administrative reasons.

This article provides step-by-step instructions on how to stop the ingestion of SAP logs into Microsoft Sentinel and disable theStopping data connector agent.collection has two parts:

If you're using

  1. Disable or remove the agentless data connector, removeconnector so Microsoft Sentinel stops polling your SAP system.
  2. Reverse the data connector and solution from Microsoft Sentinel, and then clean up any resources andSAP-side configuration you applied when you prepared your SAP system for the integration.

    , if you no longer plan to ingest SAP data.

Prerequisites

Before you stop the data collection from your SAP applications, ensure you have administrative access to:

  • The Log Analytics workspace that's enabled for Microsoft Sentinel. For more information, see Roles and permissions in Microsoft Sentinel.
  • TheYour SAP data connector agent machinesystem, so you can reverse the ABAP role and connectivity configuration.
  • Your SAP Cloud Integration tenant, so you can pause or container.undeploy the Data Collector integration flow.

Stop log ingestion and disable the connector

To stop ingestingingestion without permanently removing the connector, pause the Data Collector integration flow in SAP logs intoCloud Integration. Microsoft Sentinel and to stopstops receiving new records until you redeploy the data stream from the Docker container, sign into your data connector agent machine and run:integration flow.

docker stop sapcon-[SID/agent-name]

The Docker container stops and doesn't send any more SAP logs to Microsoft Sentinel. Stopping the Docker container stops both the ingestion and billing for the SAP system related to the connector.

If you need to reenable the Docker container, sign into the data connector agent machine and run:

docker start sapcon-[SID]

To stop ingesting a specific SID for a multi-SID container, make sure that you also delete the SID from the connector page UI in Microsoft Sentinel. Deleting the SID from the connector page UI is relevant only if you deployed the agent via the portal.ingestion permanently:

  1. In Microsoft Sentinel, select Configuration > Data connectors and search for Microsoft Sentinel for SAP - agentless.
  2. Select the data connector row and then select Open connector page in the side pane.
  3. InUnder Configuration, remove each configured SAP system (SID). Removing every SID stops ingestion and billing for those systems.
  4. Undeploy the ConfigurationData Collector area onintegration flow from SAP Cloud Integration.
  5. Optionally, delete the Microsoft Sentineldata collection rule (DCR), data collection endpoint (DCE), and the Entra ID app registration that were created for SAP data connector page, locate the SID agent you want to remove and select Delete.connector.

Remove the user role and any optional CR installed onfrom your ABAP system

If you're turning offstopping ingestion and don't plan to reconnect, remove the SAP data connectorABAP user, the MSFTSEN_SENTINEL_READER role, and stopping log ingestion fromany optional Change Requests you installed while preparing your SAP system, you might want to also remove the user role and optional CRs installed on your ABAP system.

To do so, import the deletion CR NPLK900259 into your ABAP system. For more information, see the SAP documentation.

Related content

For more information, see: